Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15205— Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup

Quick assessment

Affected
Unknown Paymob for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Paymob for WooCommerce 这款 WordPress 插件在 4.1.9 版本之前存在严重安全漏洞。具体来说,插件在公共、无需身份验证的支付回调处理中,未对客户端提供的标识符进行适当清理,就将其直接用于 SQL 查询,并且该查询在执行前未验证支付提供商的 HMAC 签名。此漏洞允许未经身份验证的攻击者通过带外(反射式)和基于时间的盲注两种方式进行 SQL 注入,从而从数据库中读取任意数据,包括用户凭据和其他敏感信息。

AI Predicted 9.8 Difficulty: Easy EPSS 0.45% · P36

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Paymob for WooCommerce < 4.1.9 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15205

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup
Source: CVE Program / CVE List V5
Vulnerability Description
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user credentials and other secrets — through both in-band (reflected) and time-based blind extraction.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Paymob for WooCommerce 0 ~ 4.1.9 -

II. Public POCs for CVE-2026-15205

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15205

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-15205 (1)

Same Patch Batch · Unknown · 2026-08-14 · 4 CVEs total

CVE-2026-16739 Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery
CVE-2026-14290 Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Att
CVE-2026-18039 Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom P

IV. Related Vulnerabilities

V. Comments for CVE-2026-15205

No comments yet


Leave a comment